Attacks on Shamir's 'RSA for paranoids'

Gilbert, H;Quisquater, Jean-Jacques;Gupta, D;Odlyzko, A
(1998) Information Processing Letters — Vol. 68, n° 4, p. 197-199 (1998)

Files

pdfdocument.pdf
  • Restricted Access
  • Adobe PDF
  • 268.88 KB

Details

Authors
Abstract
In order to allow for efficient use of extremely large moduli, Adi Shamir has proposed a variant of RSA in which one of the two prime factors is much smaller than the other. This node points out that unless special precautions are taken, simple implementations of Shamir's idea are subject to protocol attacks that recover the secret keys. (C) 1998 Published by Elsevier Science B.V. All rights reserved.
Affiliations

Citations

Gilbert, H., Quisquater, J.-J., Gupta, D., & Odlyzko, A. (1998). Attacks on Shamir’s ‘RSA for paranoids’. Information Processing Letters, 68(4), 197-199. https://doi.org/10.1016/S0020-0190(98)00160-4 (Original work published 1998)